Skip to content

JupyterLab

v4.5.7 Security

This release includes 3 security fixes for security teams reviewing exposed deployments.

Published 1mo Editors & IDEs
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 3 known CVEs

Topics

jupyter jupyterlab

Summary

AI summary

Security patches for CVE-2026-42557, CVE-2026-42266, and CVE-2026-40171.

Full changelog

4.5.7

(Full Changelog)

Security patches

The details of advisories are under embargo until JupyterLab and Notebook releases land on supported distribution channels.

  • CVE-2026-42557 https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-mqcg-5x36-vfcg
  • CVE-2026-42266 https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-37w4-hwhx-4rc4
  • CVE-2026-40171 https://github.com/jupyter/notebook/security/advisories/GHSA-rch3-82jr-f9w9

Bugs fixed

Maintenance and upkeep improvements

Documentation improvements

Contributors to this release

The following people contributed discussions, new ideas, code and documentation contributions, and review.
See our definition of contributors.

(GitHub contributors page for this release)

@Carreau (activity) | @filipeoliveira05 (activity) | @flaviomartins (activity) | @itsmejay80 (activity) | @jtpio (activity) | @krassowski (activity) | @martinRenou (activity) | @MUFFANUJ (activity) | @utsav-develops (activity)

Security Fixes

  • CVE-2026-42557 — https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-mqcg-5x36-vfcg
  • CVE-2026-42266 — https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-37w4-hwhx-4rc4
  • CVE-2026-40171 (Notebook) — https://github.com/jupyter/notebook/security/advisories/GHSA-rch3-82jr-f9w9

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track JupyterLab

Get notified when new releases ship.

Sign up free

About JupyterLab

Web-based environment for interactive and reproducible computing.

All releases →

Beta — feedback welcome: [email protected]